Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
2023-11-11T01:15:07.357
2024-11-21T08:29:25.480
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openvpn | openvpn | ≤ 2.6.6 | Yes |
Application | openvpn | openvpn_access_server | ≤ 2.11.3 | Yes |
Application | openvpn | openvpn_access_server | < 2.12.2 | Yes |
Operating System | debian | debian_linux | 12.0 | Yes |
Operating System | fedoraproject | fedora | 39 | Yes |